The privacy risks (very nicely outlined herein) are one of the core motivations for the personal assistant system I'm currently building for myself. That and I really want the hackability I get from a system I fully control (Per-task encrypted secrets? Seamless local models? Cyberdeck integration?)

Matthew Green

I wrote a new post about the privacy risks of on-phone agents like Apple’s new Siri, and how private inference isn’t any sort of silver bullet. blog.cryptographyengineering.com/2026/06/09/a...